PT-2026-95980 · Noncegeek · Dim-Sum-App

·

CVE-2026-94038

·

Published

2026-09-20

·

Updated

2026-09-21

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NonceGeek dim-sum-app (affected versions not specified)
Description An issue in the Deno Backend component within the file deno/main.tsx allows for server-side request forgery, a technique where an attacker induces the server to make requests to an unintended location. This occurs through the manipulation of the supabase url argument in the textSearchV2Handler() function. The attack can be executed remotely.
Recommendations Apply patch 8389032e5d52c28c4855c6126ca7d0eae8af346a. As a temporary workaround, restrict the use of the supabase url argument in the textSearchV2Handler() function.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94038

Affected Products

Dim-Sum-App